Unofficial Windows x64 binary overlay for the OpenAI Codex CLI.
LPM flags this version as an AI-agent control-surface risk. On global npm installation, a postinstall hook replaces executables in the separate @openai Codex package with bundled native binaries. This is an unconsented lifecycle mutation of a foreign AI-agent control surface.
Package defines install-time lifecycle scripts.
package.jsonView on unpkgAn automatic postinstall runs the installer.
package.jsonView on unpkg · L40Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgSource fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/powershell.jsView on unpkgThe lifecycle wrapper launches PowerShell with execution-policy bypass.
bin/powershell.jsView on unpkg · L22The installer locates the separate global @openai Codex package and selects its executables.
install.ps1View on unpkg · L161It backs up and then replaces the foreign Codex and apply_patch executables with bundled binaries.
install.ps1View on unpkg · L175This report applies to @chenronggui/codex-win-patch@0.153.4-patch.3.
See version security history for other recorded verdicts.
Evidence last updated: .
Package defines install-time lifecycle scripts.
package.jsonView on unpkgAn automatic postinstall runs the installer.
package.jsonView on unpkg · L40Install-time lifecycle script is not statically allowlisted and needs review.
package.jsonView on unpkgThe lifecycle wrapper launches PowerShell with execution-policy bypass.
bin/powershell.jsView on unpkg · L22Source fingerprint signature matches a known malicious package signature; route for source-aware review.
bin/powershell.jsView on unpkgThe installer locates the separate global @openai Codex package and selects its executables.
install.ps1View on unpkg · L161It backs up and then replaces the foreign Codex and apply_patch executables with bundled binaries.
install.ps1View on unpkg · L175